How Does PCI DSS 4.0 Change Card Data Security?

179 views
•
August 22, 2022
by
RSAC Cybersecurity
YouTube video player
How Does PCI DSS 4.0 Change Card Data Security?

TL;DR

PCI DSS 4.0 expands cardholder-data protection with 64 new requirements, including stronger cryptographic protection, tighter controls for system accounts, broader multi-factor authentication, authenticated vulnerability scans, and defenses against phishing and e-commerce skimming. It also introduces risk-based scheduling and two compliance-validation paths, while raising a larger question: whether redesigning payment systems could eventually make stolen card data useless and reduce the standard’s relevance.

Transcript

Um, last time there was a PCI DSS session at RSA Conference, it was map-- it was very exciting. It was called Mapping PCI DSS to the NIST Cybersecurity Framework. It was basically a talk about a spreadsheet. The room was a lot fuller, and maybe that's gonna answer my question of whether this is actually an omen of, um, extinction, that fewer people... Read More

Key Insights

  • PCI DSS is a contractual security standard that applies to every entity storing, processing, or transmitting cardholder data. It is generally enforced through agreements among merchants, acquirers, card brands, and service providers, although it has also become law in some jurisdictions.
  • PCI DSS exists partly because payment-card fraud created an asymmetric risk. A merchant losing a million card numbers might otherwise bear no direct cost, so contractual consequences give merchants a financial reason to account for the risk and protect cardholder data.
  • PCI DSS 4.0 contains 64 new requirements, including 13 policy-oriented requirements and 51 technological requirements. These additions respond to changes in security threats, attacker behavior, and underlying technology during the standard’s eight-year development timetable.
  • Risk-based scheduling gives organizations limited flexibility over how frequently some controls operate. Instead of always prescribing quarterly, monthly, or weekly activity, version 4.0 sometimes permits a frequency determined through the organization’s own documented risk assessment.
  • Stored cardholder data requires stronger cryptographic protection under version 4.0. Hashes must be full cryptographic hashes, such as an HMAC with key management, while transparent whole-disk or whole-partition encryption cannot substitute for file-level or field-level encryption.
  • System and application accounts receive substantial new controls because they have been involved in compromises. Each account requires documented least privilege, strong passwords, and risk-based password changes, while accounts used for interactive login effectively require privileged-access-management capabilities.
  • Multi-factor authentication is required for all access into the cardholder data environment under version 4.0. This expands the earlier focus on remote or administrative access and makes authentication a broader baseline for protecting systems that handle cardholder data.
  • Authenticated quarterly internal vulnerability scans and protections against phishing create significant implementation work. Large environments may require years of preparation for authenticated scanning, while organizations must deploy technology against phishing and train users to report suspected phishing attempts.

Install to Summarize YouTube Videos and Get Transcripts

Explore YouTube Video Summarizer or Get YouTube Transcript Extractor

Questions & Answers

Q: What is PCI DSS and who must comply with it?

PCI DSS is a written security standard developed by the Payment Card Industry Security Standards Council, which is owned and managed by American Express, Discover, Mastercard, Visa, JCB, and UnionPay. It applies to all entities that store, process, or transmit cardholder data. Compliance is usually a contractual obligation connecting merchants, acquirers, card brands, companies, and service providers, although some jurisdictions have also made it law.

Q: Why was PCI DSS originally created?

PCI DSS was created in response to criminals stealing payment card data, primarily from magnetic-stripe point-of-sale systems, and using that information to commit fraud. It was intended to make organizations protect cardholder data, reduce pressure for federal regulation, and correct an asymmetric-risk problem in which a merchant could lose a million card numbers without necessarily bearing the resulting financial cost.

Q: What are the main changes in PCI DSS 4.0?

PCI DSS 4.0 introduces 64 new requirements, consisting of 13 policy-oriented requirements and 51 technological requirements. Major changes include limited risk-based flexibility for setting control frequencies, defined and customized approaches to compliance validation, stronger cryptographic protections, controls for system and application accounts, broader multi-factor authentication, authenticated internal vulnerability scans, and measures addressing phishing and e-commerce skimming.

Q: When does PCI DSS 4.0 become mandatory?

PCI DSS 4.0 was published at the end of March 2022 after a development process that began in 2017. Organizations can continue using the current version through March 31, 2024. Version 4 becomes the effective standard on April 1, 2024, while the new technological requirements become effective one year later, on April 1, 2025.

Q: How does risk assessment affect PCI DSS 4.0 controls?

PCI DSS 4.0 allows a limited amount of risk-based decision-making for the timing of certain activities. Earlier requirements often mandated a fixed quarterly, monthly, or weekly schedule. Some version 4.0 requirements instead permit organizations to establish a frequency through their own risk assessment. This provides flexibility, but the selected timing must still be supported by an explicit assessment rather than convenience alone.

Q: How must stored cardholder data be encrypted under PCI DSS 4.0?

PCI DSS 4.0 no longer accepts transparent whole-disk or whole-partition encryption as sufficient protection for stored cardholder data. Organizations relying on encryption must protect the data at the file or field level. Hashing must also use a full cryptographic construction, with the presentation identifying an HMAC supported by key management as an example of the required approach.

Q: What controls apply to system and application accounts in PCI DSS 4.0?

Every system and application account must receive least privilege, and that assigned privilege must be documented so an assessor can validate it. These accounts also require strong passwords and password changes at intervals determined through a risk assessment. If a system or application account supports interactive login, the organization effectively needs a privileged access management solution to control that use.

Q: How does PCI DSS 4.0 change authentication and phishing defenses?

PCI DSS 4.0 requires multi-factor authentication for all access into the cardholder data environment, expanding beyond remote or administrative access. Quarterly internal vulnerability scans must also be authenticated, which can require extensive preparation in large environments. Organizations additionally need technology that protects users against phishing and training that teaches users to report phishing attempts they encounter.

Summary & Key Takeaways

  • PCI DSS is a written security standard for entities that store, process, or transmit cardholder data. Six card brands own and manage the PCI Security Standards Council. Compliance is generally enforced through contracts rather than law, although some countries and United States jurisdictions have incorporated its requirements into their laws.

  • PCI DSS originally addressed criminals stealing payment card data, especially from magnetic-stripe point-of-sale systems, and using it for fraud. The standard also helped discourage government regulation, transferred some financial impact of breaches to merchants, and provided organizations with instructions for protecting cardholder data across the global payment ecosystem.

  • Version 4.0 was published in March 2022 after development began in 2017 and more than 3,000 comments were individually reviewed. Version 3 remains usable through March 31, 2024. Version 4 then becomes mandatory, while its new technological requirements become effective on April 1, 2025.


Read in Other Languages (beta)

Share This Summary 📚

Explore More Summaries from RSAC Cybersecurity 📚